Impact
The LS Google Map Router plugin for WordPress contains a stored cross‑site scripting flaw that is triggered via the 'map_type' shortcode attribute. Insufficient input sanitization and output escaping allow an authenticated user with Contributor access or higher to embed arbitrary JavaScript. When a user visits a page containing the injected shortcode, the script executes under the victim’s browser context, risking theft of credentials, session hijacking, or defacement.
Affected Systems
The vulnerability affects the LS Google Map Router plugin by ladislavsoukupgmailcom, all WordPress installations running any version up to and including 1.1.0.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. With an EPSS less than 1% the likelihood of active exploitation in the wild appears low, and the vulnerability is not catalogued in the CISA KEV list. However, the requirement for Contributor‑level authentication means the attack surface is limited to users already granted content‑creation privileges. Attackers can craft a malicious shortcode in the plugin interface or edit content, and the injected script will persist until removed. Given the limited privilege requirement and the potential for cross‑site attacks, administrators should treat it as a moderate‑risk internal threat and apply remediation promptly.
OpenCVE Enrichment